More Info:

Avoid creating guest users, as they are typically added outside your employee on-boarding/off-boarding process and could potentially be overlooked indefinitely leading to a potential vulnerability.

Risk Level

Medium

Address

Security

Compliance Standards

HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

The presence of guest users in an Azure Active Directory (AD) can pose a security risk. Here are the steps to remediate the issue of guest users in use in Azure:

  1. Sign in to the Azure portal using your administrator credentials.
  2. In the left-hand menu, click on “Azure Active Directory”.
  3. Under “Manage”, select “Users”.
  4. On the “Users” page, click on the “Guest users” tab.
  5. Review the list of guest users to determine which ones need to be removed.
  6. Select the guest user that you want to remove by clicking on the checkbox next to their name.
  7. Click on the “Remove” button at the top of the screen.
  8. Confirm that you want to remove the guest user by clicking “Yes” in the confirmation dialog box.

Repeat steps 6-8 for each guest user that you want to remove.

Note: Before removing a guest user, make sure that they no longer require access to any resources in your Azure environment.